Process · CMMC Guide

CMMC POA&M Requirements: What's Allowed, What's Not, and How to Close Gaps Fast

A POA&M is neither a free pass nor an automatic failure. It is a time-bound commitment with rules.

ProcessPOA&M

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 17, 2026 · 5 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

The CMMC program rule (32 CFR part 170) has been in effect since December 16, 2024, and it sets specific rules for the Plan of Action and Milestones (POA&M). The POA&M is easy to misread in both directions: as a free pass, or as proof that any open item means automatic failure. Both readings are wrong.

A POA&M is a structured remediation plan with rules, timelines, and real consequences if you get it wrong. This guide breaks down POA&M requirements for CMMC Level 2: what the rule allows, what a credible entry contains, the mistakes that put Conditional status at risk, and how to manage POA&Ms without drowning in spreadsheets.

What is a POA&M, and how does it fit into CMMC?

A Plan of Action and Milestones identifies security weaknesses in your environment, maps them to specific NIST SP 800-171 controls, and lays out a concrete plan with milestones, responsible parties, and deadlines to remediate each gap.

In CMMC, a POA&M lets an Organization Seeking Assessment reach a Conditional CMMC Status, Conditional Level 2 (Self) or Conditional Level 2 (C3PAO), while it remediates a limited set of requirements scored NOT MET (32 CFR 170.21(a)). A POA&M is not permitted at any time for Level 1 (32 CFR 170.21(a)(1)). This is not a free pass. It is a structured, time-bound commitment.

Under CMMC, POA&M items carry scoring consequences, a 180-day closeout deadline, and specific exclusions on which requirements can appear on a POA&M at all (32 CFR 170.21).

What CMMC allows, and doesn't allow, on a POA&M

Not every failed control qualifies for POA&M treatment. CMMC Level 2 separates requirements that can be remediated after the assessment from those that must be MET at the time of the assessment.

Controls eligible for a POA&M

For CMMC Level 2, a requirement scored NOT MET may be carried on a POA&M only when all three conditions in 32 CFR 170.21(a)(2) hold: the assessment score is at least 80% of the 110 Level 2 requirements (88 points or more); every requirement on the POA&M is worth 1 point in the CMMC Scoring Methodology (32 CFR 170.24), with one exception, SC.L2-3.13.11 CUI Encryption, which may be included when encryption is employed but is not FIPS-validated; and none of the six requirements listed below is on it. The closing of the POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date, or the Conditional status expires (32 CFR 170.21(b)).

Controls that cannot be on a POA&M

Any requirement worth 3 or 5 points must be MET at the time of assessment, apart from the SC.L2-3.13.11 case above. Six more requirements may never be on a POA&M, whatever their point value (32 CFR 170.21(a)(2)(iii)): AC.L2-3.1.20 External Connections, AC.L2-3.1.22 Control Public Information, CA.L2-3.12.4 System Security Plan, PE.L2-3.10.3 Escort Visitors, PE.L2-3.10.4 Physical Access Logs, and PE.L2-3.10.5 Manage Physical Access.

Scoring implications: under the CMMC Scoring Methodology the maximum Level 2 score equals the number of Level 2 requirements, 110, and each requirement NOT MET subtracts its value (1, 3 or 5) from that maximum, which can produce a negative score (32 CFR 170.24(c)(2)). Requirements on a POA&M are NOT MET, so they count against the score until they are closed. A Level 2 self-assessment score is entered in the Supplier Performance Risk System (SPRS) (32 CFR 170.16(a)(1)(i)).

Before you decide what belongs on a POA&M, you need to know which controls you actually meet. A free 10-question gap check gives you a directional self-assessment (not an official SPRS score).

Run the free gap check →

Anatomy of an effective POA&M entry

Each entry is a structured commitment. Here is what goes into a credible one.

What makes an entry credible

POA&M mistakes that put Conditional status at risk

How AaaS platforms streamline POA&M management

A POA&M kept in a spreadsheet stays current only while someone remembers to update it: copies multiply and dates go stale. An Agent-as-a-Service (AaaS) platform built for CMMC turns POA&M upkeep from a manual tracking exercise into a plan re-issued every cycle, giving your team leverage rather than adding headcount.

If your POA&M strategy today is a shared spreadsheet, start by finding out where you actually stand. Run the free gap check, then map your real posture with the $999 CMMC Level 2 Readiness Snapshot.

Source: 32 CFR 170.16, 170.21 and 170.24, as published in the CMMC Program final rule, 89 FR 83092 (Oct. 15, 2024); NIST SP 800-171 Rev. 2. This article is general guidance, not legal or compliance advice. Confirm the POA&M rules against the current eCFR text before you build your plan.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-requirement NIST SP 800-171 Rev. 2 baseline; it measures only the requirements a connected source can show, and returns a PDF of your top gaps within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Readiness subscriptions are billed annually, with a month-to-month option on every tier.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures attributed to the DoD are its published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.